Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7m5q-w7p8-x8h4

Опубликовано: 29 нояб. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

An integer overflow and buffer overflow issues were found in the ACPI Error Record Serialization Table (ERST) device of QEMU in the read_erst_record() and write_erst_record() functions. Both issues may allow the guest to overrun the host buffer allocated for the ERST memory device. A malicious guest could use these flaws to crash the QEMU process on the host.

An integer overflow and buffer overflow issues were found in the ACPI Error Record Serialization Table (ERST) device of QEMU in the read_erst_record() and write_erst_record() functions. Both issues may allow the guest to overrun the host buffer allocated for the ERST memory device. A malicious guest could use these flaws to crash the QEMU process on the host.

EPSS

Процентиль: 5%
0.00023
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-120
CWE-190

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 2 лет назад

An integer overflow and buffer overflow issues were found in the ACPI Error Record Serialization Table (ERST) device of QEMU in the read_erst_record() and write_erst_record() functions. Both issues may allow the guest to overrun the host buffer allocated for the ERST memory device. A malicious guest could use these flaws to crash the QEMU process on the host.

CVSS3: 6
redhat
больше 2 лет назад

An integer overflow and buffer overflow issues were found in the ACPI Error Record Serialization Table (ERST) device of QEMU in the read_erst_record() and write_erst_record() functions. Both issues may allow the guest to overrun the host buffer allocated for the ERST memory device. A malicious guest could use these flaws to crash the QEMU process on the host.

CVSS3: 6.5
nvd
больше 2 лет назад

An integer overflow and buffer overflow issues were found in the ACPI Error Record Serialization Table (ERST) device of QEMU in the read_erst_record() and write_erst_record() functions. Both issues may allow the guest to overrun the host buffer allocated for the ERST memory device. A malicious guest could use these flaws to crash the QEMU process on the host.

CVSS3: 6.5
debian
больше 2 лет назад

An integer overflow and buffer overflow issues were found in the ACPI ...

CVSS3: 6.5
fstec
больше 2 лет назад

Уязвимость функций read_erst_record() и write_erst_record() эмулятора аппаратного обеспечения QEMU, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 5%
0.00023
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-120
CWE-190